Daily Briefing
Today's outlook
Citrix NetScaler flaw is being exploited now; Chrome ships five critical fixes
Good morning. Patch Citrix first. CISA lists CVE-2026-88779 on its Known Exploited Vulnerabilities catalog and records it as known to be exploited. Citrix's advisory covers NetScaler ADC 13.1 up to the fix in 13.1-37.282; the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H carries a base score of 7.5, an availability-only impact reachable over the network with no authentication or user interaction. CISA directs stakeholders to apply mitigations in line with the vendor advisory and BOD 26-04, or discontinue use if no mitigation is available.
Google patched five critical Chrome flaws, each scored CVSS 9.6 against the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H: CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382. Google's advisory lists the fix in Chrome 155.0.8059.39. None is on CISA's KEV catalog. Update the browser and confirm the build.
Exploitation in the wild, by outlet. BleepingComputer reported hackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue admin accounts. BleepingComputer also reported Atlassian is warning of a critical arbitrary file-access flaw in self-hosted Data Center products including Confluence, Jira and Bitbucket. And BleepingComputer reported that on day one of Pwn2Own Ireland 2026 researchers exploited 32 zero-days, hacking the Samsung Galaxy S26 twice and earning $388,500.
Breaches and campaigns. BleepingComputer reported ASOS confirmed a data breach after attackers sent unauthorized push notifications through its app and claimed to have stolen customer data from its Snowflake environment. SecurityWeek reported the FBI removed an Accenture contractor over a breach it blames on a missed patch, which exposed personal data of thousands of bureau employees. The Record reported South Korean officials believe AI agents and a Chinese cybersecurity tool were used to breach at least seven financial institutions, exposing data on at least 68,000 people. BleepingComputer and The Hacker News reported a human-operated phishing platform using fake ChatGPT, Gemini, Claude and Perplexity ad portals to steal credentials and MFA codes via browser-in-browser attacks.
Also note: CISA published an advisory for Hitachi Energy RTU500 end-of-life CMU firmware 9.x, from findings reported by Dragos; and Schneier on Security, citing 404Media, reports a cyber-weapons manufacturer is exploiting an iOS flaw to bypass the automatic reboot that secures an idle iPhone after 72 hours.
Zoom out: Only the Citrix flaw is listed as exploited; the five critical Chrome bugs are not on CISA's catalog.
Vulnerability in focus
CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.
Affected: citrix-adc.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- The Register: Anthropic reconfigures its cool kids security program Read it
- BleepingComputer: Ninja Forms plugin flaw exploited to hack WordPress sites Read it
- The Hacker News: Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes Read it
- The Record: Alleged ATM malware creator appears in Nebraska court after arrest Read it
Sources
- Anthropic reconfigures its cool kids security program The Register
- Ninja Forms plugin flaw exploited to hack WordPress sites BleepingComputer
- Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes The Hacker News
- Alleged ATM malware creator appears in Nebraska court after arrest The Record
- FBI Blames Contractor’s Missed Patch for ShinyHunters Breach SecurityWeek
- Anaconda combines agent swarms with autonomous security testing Help Net Security
- Hitachi Energy RTU500 CISA
- Possible Vulnerability in Apple’s Automatic Reboot Schneier on Security
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland BleepingComputer
- Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan The Hacker News
- Atlassian warns of critical file-access flaw in Jira, Confluence BleepingComputer
- ASOS confirms data breach after “HACKED” in-app notifications BleepingComputer
- South Korean officials believe AI agents were used to hack several banks The Record
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes BleepingComputer
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.